This document is under active development and has not been finalized.
Skip to content

Backup Strategy

3-2-1 Rule in Detail

Backup Types

TypeDescriptionIntervalStorage Requirement
Full backupComplete backup of all dataWeekly (Sunday)100%
IncrementalOnly data changed since last backupDaily~5-15%
Configuration backupGit-based versioning of all configsUpon every changeMinimal

Backup Targets by Data Type

Data TypePrimary BackupSecondary BackupOffsiteEncryptionRetention
DatabasesLocal storageObject storage (cloud)YesAES-25690 days
Customer dataLocal storageObject storage (cloud)YesAES-256Per contract, min. 30d
Server configurationsGit repositoryRemote repositoryYesRepository-levelIndefinite
Email archiveLocal storageObject storageYesAES-25690 days
Key materialEncrypted vaultOffline copyYes (physically separated)AES-256 + passphraseLifetime of the key

3-2-1 RULE

Maintain at least 3 copies of data, on 2 different media types, with 1 copy stored offsite. This principle is the foundation for resilient data protection per §30(2) No. 3 BSIG.

Restore Verification

TestIntervalScopeAcceptance Criterion
Automated integrity checkWith every backupChecksumChecksum matches
Restore test (sample)MonthlyIndividual files / databasesData correct and complete
Full restore testQuarterlyComplete systemRTO met, data consistent
DR simulationAnnuallyEntire infrastructureAll RTO/RPO targets achieved

Monitoring

  • Backup success/failure is monitored automatically
  • Failed backups generate immediate alerts
  • Storage capacity and retention periods are monitored
  • Monthly backup report to CISO

Documentation licensed under CC BY-NC 4.0 · Code licensed under MIT